Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2023-6438

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /WebArticle/articles/ of the component Like Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246438 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-40833

Disclosure Date: October 12, 2023 (last updated December 08, 2023)
An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting.
Attacker Value
Unknown

CVE-2023-33356

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2023-33355

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.